peter bassill · operator
$ cve CVE-2015-2320 JSON

CVE-2015-2320

9.8
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.54% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-295
On CISA KEVno
Public exploitnone known
Published2018-01-08
Last modified2026-06-17

Affected (2)

VendorProduct
debiandebian linux
mono-projectmono

References

→ the Explorer  ·  watch your stack  ·  NVD